Security

Security is the foundation, not a feature.

LoopLlama runs your agents against real systems and real data. We design for isolation, encryption, and auditability from the first line of code.

How we protect your data

Encryption everywhere

Data is encrypted in transit with TLS 1.2+ and at rest by our database provider. Connector OAuth tokens, connector credentials, and webhook signing secrets are additionally encrypted with AES-256-GCM under a key that never lives in the database.

Tenant isolation

Every workflow, run, key, connector, and webhook is scoped to your account and checked on every request. One account can never read or trigger another account's resources.

Least-privilege access

Role-based access controls govern the dashboard and API — new accounts can view but not run anything until approved. API keys are stored as bcrypt hashes and can be revoked instantly.

We never train on your data

Workflow inputs and outputs belong to you. We do not use customer data to train models, and we don't share it with third parties beyond the model providers needed to run your workflows.

Auditability

Per-step traces record every model call and tool invocation. An append-only audit log records administrative actions. Human-in-the-loop gates let you require approval before an agent sends email or writes to a CRM.

Secure development

Every change is reviewed before it ships. Secrets live only in the deployment environment, never in source control. Dependencies are kept current.

Compliance & data handling

Compliance status

LoopLlama does not yet hold a SOC 2 report or HIPAA certification. We'll complete your security questionnaire and describe our controls candidly — ask us.

Data processing

We can sign a DPA covering GDPR and CCPA obligations on Business and Enterprise plans. We never train on your data, and you can delete workflows and run history at any time.

Deployment options

Enterprise customers can run LoopLlama as a single-tenant deployment in a dedicated VPC to meet residency and isolation requirements.

Responsible disclosure

We welcome reports from security researchers. If you believe you've found a vulnerability, email security@loopllama.ai with steps to reproduce. We'll acknowledge your report within one business day and keep you updated as we investigate. Please give us a reasonable window to remediate before any public disclosure, and avoid accessing or modifying data that isn't yours while testing.

Need our security documentation?

We're happy to complete a security questionnaire or walk your team through our architecture and controls.

Contact us